You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Pod中openssh-server SSH连接失败:Connection reset by <IP> port 30500求助

问题:K8s Pod中部署openssh-server后SSH连接报错Connection reset by port 30500

sshd服务器日志

debug2: load_server_config: filename /etc/ssh/sshd_config
debug2: load_server_config: done config len = 806
debug2: parse_server_config: config /etc/ssh/sshd_config len 806
debug3: /etc/ssh/sshd_config:17 setting Port 30500
debug3: /etc/ssh/sshd_config:19 setting ListenAddress 0.0.0.0
debug3: /etc/ssh/sshd_config:22 setting HostKey /etc/ssh/ssh_host_rsa_key
debug3: /etc/ssh/sshd_config:23 setting HostKey /etc/ssh/ssh_host_ecdsa_key
debug3: /etc/ssh/sshd_config:24 setting HostKey /etc/ssh/ssh_host_ed25519_key
debug3: /etc/ssh/sshd_config:36 setting SyslogFacility AUTH
debug3: /etc/ssh/sshd_config:38 setting LogLevel VERBOSE
debug3: /etc/ssh/sshd_config:43 setting PermitRootLogin yes
debug3: /etc/ssh/sshd_config:44 setting StrictModes no
debug3: /etc/ssh/sshd_config:52 setting AuthorizedKeysFile .ssh/authorized_keys
debug3: /etc/ssh/sshd_config:60 setting HostbasedAuthentication no
debug3: /etc/ssh/sshd_config:68 setting PasswordAuthentication no
debug3: /etc/ssh/sshd_config:73 setting ChallengeResponseAuthentication no
debug3: /etc/ssh/sshd_config:83 setting GSSAPIAuthentication no
debug3: /etc/ssh/sshd_config:84 setting GSSAPICleanupCredentials no
debug3: /etc/ssh/sshd_config:105 setting X11Forwarding yes
debug3: /etc/ssh/sshd_config:131 setting AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES
debug3: /etc/ssh/sshd_config:132 setting AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT
debug3: /etc/ssh/sshd_config:133 setting AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE
debug3: /etc/ssh/sshd_config:134 setting AcceptEnv XMODIFIERS
debug3: /etc/ssh/sshd_config:137 setting Subsystem sftp    /usr/libexec/openssh/sftp-server
debug1: sshd version OpenSSH_7.4, OpenSSL 1.0.2k-fips  26 Jan 2017
debug1: private host key #0: ssh-rsa SHA256:6XsUKJrlEzspiLw1H/e5qfrzga/n4Rgs
debug1: private host key #1: ecdsa-sha2-nistp256 SHA256:yJkcJ2AX3E4dOADjCRn9EWnut+z5nW3xKhGOc
debug1: private host key #2: ssh-ed25519 SHA256:GHvEepwimuJpanKOXJx8Aacpcs8MwXxlmaU7Q
debug1: rexec_argv[0]='/usr/sbin/sshd'
debug1: rexec_argv[1]='-ddd'
debug3: oom_adjust_setup
debug1: Set /proc/self/oom_score_adj from 1000 to -1000
debug2: fd 3 setting O_NONBLOCK
debug1: Bind to port 30500 on 0.0.0.0.
Bind to port 30500 on 0.0.0.0 failed: Address already in use.
Cannot bind any address.

SSH命令日志

ssh -vvv localhost -p 30500
OpenSSH_7.4p1, OpenSSL 1.0.2k-fips  26 Jan 2017
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 58: Applying options for *
debug2: resolving "localhost" port 30500
debug2: ssh_connect_direct: needpriv 0
debug1: Connecting to localhost [::1] port 30500.
debug1: connect to address ::1 port 30500: Connection refused
debug1: Connecting to localhost [127.0.0.1] port 30500.
debug1: Connection established.
debug1: permanently_set_uid: 0/0
debug1: key_load_public: No such file or directory
debug1: identity file /root/.ssh/id_rsa type -1
debug1: key_load_public: No such file or directory
debug1: identity file /root/.ssh/id_rsa-cert type -1
debug1: key_load_public: No such file or directory
debug1: identity file /root/.ssh/id_dsa type -1
debug1: key_load_public: No such file or directory
debug1: identity file /root/.ssh/id_dsa-cert type -1
debug1: key_load_public: No such file or directory
debug1: identity file /root/.ssh/id_ecdsa type -1
debug1: key_load_public: No such file or directory
debug1: identity file /root/.ssh/id_ecdsa-cert type -1
debug1: key_load_public: No such file or directory
debug1: identity file /root/.ssh/id_ed25519 type -1
debug1: key_load_public: No such file or directory
debug1: identity file /root/.ssh/id_ed25519-cert type -1
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_7.4
debug1: Remote protocol version 2.0, remote software version OpenSSH_7.4
debug1: match: OpenSSH_7.4 pat OpenSSH* compat 0x04000000
debug2: fd 3 setting O_NONBLOCK
debug1: Authenticating to localhost:30500 as 'root'
debug3: put_host_port: [localhost]:30500
debug3: send packet: type 20
debug1: SSH2_MSG_KEXINIT sent
Connection reset by 127.0.0.1 port 30500

服务器运行状态

netstat -anp | grep 30500
tcp        0      0 0.0.0.0:30500           0.0.0.0:*               LISTEN      1/sshd

观察结果

  • 同一镜像在本地Docker容器中运行正常(临时允许密码认证的相同sshd_config)
  • 服务已关联正确端点,可telnet到自定义SSH端口30500
  • SSH进程在Pod中正常运行
  • 从其他Pod或集群外telnet到SSH端口均正常
  • 同一Pod内运行在80端口的nginx容器工作正常
  • 当前错误情况:
    • NodePort或LoadBalancer(OCI)均无法正常工作
    • 从Pod内部、其他Pod或工作节点SSH到localhost均失败

解决建议

1. 修复sshd进程启动异常

sshd启动日志显示端口绑定失败,但netstat显示PID 1的sshd在监听,说明进程可能处于异常状态:

  • 进入Pod执行ps aux,检查是否存在多个sshd进程,确认PID 1的sshd是否正常运行
  • 杀死现有sshd进程并重新启动:
    kill 1 && /usr/sbin/sshd -D
    
    用-D参数让sshd前台运行,适配容器环境,避免后台运行导致的进程管理问题

2. 调整认证配置排除认证失败

SSH客户端日志显示没有可用的密钥文件,同时sshd配置禁用了密码认证(PasswordAuthentication no),这会导致认证失败进而连接被重置:

  • 临时修改/etc/ssh/sshd_config,设置PasswordAuthentication yes,重启sshd后用密码测试连接
  • 如果需要密钥认证,确保客户端的公钥已添加到Pod内/root/.ssh/authorized_keys文件中,且文件权限为600,目录权限为700

3. 确保主机密钥正确生成

容器启动时如果没有预先生成SSH主机密钥,可能导致连接异常:

  • 在容器启动脚本中添加生成主机密钥的命令:
    ssh-keygen -A
    
    确保sshd启动前完成密钥生成

4. 排查端口冲突与容器网络限制

  • 检查Pod内是否有其他进程占用30500端口,执行lsof -i :30500确认(若未安装lsof,用netstat -tulpn)
  • 检查Kubernetes NetworkPolicy是否限制了SSH流量,确保相关Pod、节点之间的30500端口允许通信
  • 临时关闭容器内的SELinux(执行setenforce 0),测试是否是安全模块限制导致的连接重置

内容的提问来源于stack exchange,提问作者Arpit Jain

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 11:55:45